Original URL: https://www.theregister.com/2008/01/28/ico_acts_on_ms/

M&S rapped for data loss

This is not just security...

By John Oates

Posted in On-Prem, 28th January 2008 10:56 GMT

Marks and Spencers has been told it must encrypt all company laptops containing personal information by April 2008.

In May 2007 the knicker-seller admitted it had lost records relating to 26,000 staff when a laptop was nicked from a contractor's house. The laptop contained information on members of the company pension scheme.

M&S wrote to all staff whose information had been compromised offering free credit checks.

The Information Commissioner's Office reckons that the type of information on the laptop means it should have been protected with encryption.

The ICO has issued M&S with an Enforcement Notice - the company must ensure laptops containing sensitive information are encrypted by April, or face further action from the ICO.

The ICO wants the power to carry out spot checks on private companies and government departments when it suspects data protection is not being carried out properly. ®